Advent of Configuration Extraction – Part 3: Mapping GOT/PLT and Disassembling the SNOWLIGHT Loader
ID: d08d3692-53b5-5a55-a4c6-5091e9168fae
STIX ID: report--d08d3692-53b5-5a55-a4c6-5091e9168fae
Feed Name: Sekoia.io Blog
Date Published: 2025-12-15
Date Updated: 2026-04-29
Author: Jeremy Scion, Pierre Le Bourhis and Sekoia TDR
**SNOWLIGHT** is a compact ELF downloader used to fetch and execute remote payloads in memory; this analysis documents how to extract its C2 address and port by parsing .rodata and reconstructing GOT/PLT mappings with LIEF and disassembling main with Capstone, noting its use of memfd_create/fexecve, XOR decoding (0x99), and reported association with UNC5174/VShell intrusion activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
